Serval

Technology

SecurityEngineer,DetectionandResponse

$200–325k San Francisco, California, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Lead candidates.

The Brief

“Security Engineer, Detection and Response at Serval. Skills: Detection engineering, Incident response, Security operations, Team leadership. Design detection and response operations. Implement detection and response operations”

Industry & Context.

Technology

What They're Looking For.

Must Have

10+ years cybersecurity, Deep expertise detection engineering, Deep expertise incident response, Deep expertise security operations, Deep experience building teams, Deep experience leading teams, Stellar leadership skills, Demonstrated history driving improvements, Exceptional written communication, Exceptional verbal communication, Remain calm under pressure, Effectively run incidents, Deep expertise observability stacks, Deep expertise detection primitives, Understand modern adversary tradecraft, Experience translating TTPs, Experience into detection strategies, Experience into response actions

Nice to Have

Experience with SIEM, Experience with data lakes, Experience with EDR, Experience with cloud telemetry, Experience with logging

What You'll Do.

Design detection and response operations

Implement detection and response operations

Operate detection and response operations

Monitor security events

Triage security events

Investigate security events

Contain security events

Remediate security events

Ensure operational rigor

Ensure operational readiness

Improve detection quality

Improve detection coverage

Partner with engineering teams

Ensure telemetry availability

Ensure telemetry reliability

Ensure telemetry actionability

Embed detection and response

Build security program

How You'll Work.

Team & Collaboration

Partner with Engineering; Partner with Product; Partner with Infrastructure

Communication Scope

Written communication; Verbal communication

Full Job Description

WHO WE ARE Serval http://serval.com is an AI-native automation platform transforming how enterprises operate. We build intelligent agents that understand real-world workflows and execute them end-to-end — replacing manual processes and rigid legacy systems with adaptive, learning software. Founded in early 2024, Serval is already trusted by companies like Fox, Notion, Perplexity, Vercel, and Brex to automate high-volume, high-friction operational work across their organizations. At the core of Serval is an agentic AI platform that turns natural language into production-grade workflows. Our agents don’t just respond to requests — they reason, take action across systems, and continuously improve with usage. What began with operational use cases has quickly evolved into a horizontal AI automation layer used across IT, HR, Finance, Security, Legal, and Engineering. Our mission is to eliminate repetitive, manual work across the enterprise and give teams leverage through intelligent automation. Long term, we’re building the universal AI operations layer — a system of agents that sits across business functions and runs the workflows that keep modern companies moving. We’re backed by leading investors including Sequoia Capital, Redpoint Ventures, Meritech, First Round, General Catalyst, Elad Gil, and others. ROLE OVERVIEW As Detection and Response Lead, you'll build and scale the foundations of Serval's cybersecurity detection and response operations. You will set the strategy and drive execution for security monitoring, incident response, recovery, and post-incident improvement across our infrastructure and the systems our customers trust us to operate in. You'll be a hands-on leader with deep technical credibility and strong operational instincts. You will build and mentor a team, partner closely with Engineering and Product, and ensure that detection and response capabilities are embedded by design into the systems that power Serval. WHAT YOU'LL DO - Design, implement, a

Free ATS check

Applying for this Security Engineer, Detection and Response role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about Serval?

Real rants from real employees. Read before you apply.

Read Company Rants →